Skip to content
TEN Brief Ten verified stories a day 2026.10.11 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Reference

What an SBOM is — the software bill of materials nobody used to find Log4j

An SBOM, or software bill of materials, is a machine-readable list of the open-source libraries, versions, suppliers and dependency relationships inside a piece of software. Its purpose is to answer 'are we affected?' within minutes when a new vulnerability is disclosed. The US built SBOMs into federal software procurement after the 2021 cybersecurity executive order, and the Cybersecurity and Infrastructure Security Agency (CISA) published a draft update of the minimum elements in August 2025. The EU Cyber Resilience Act requires manufacturers to produce one when it fully applies on December 11, 2027. During the 2021 Log4j crisis, none of the nearly 80 organisations reviewed by the US Cyber Safety Review Board used a software inventory to find vulnerable deployments

An engineer seen from behind sorting component trays on a sunlit workbench

The three lines

  • Definition — a machine-readable list of components: libraries, versions, suppliers, dependencies
  • Purpose — answer 'are we affected?' fast when a bug drops; without one, Log4j took weeks
  • Rules — US federal procurement; EU Cyber Resilience Act obligation from December 11, 2027

Key questions

What is an SBOM
**A software 'ingredients list' written for machines to read.** | Item | Detail | |---|---| | Full name | Software Bill of Materials | | Contents | Component names, versions, suppliers, unique IDs, dependencies | | Standard formats | SPDX, CycloneDX | | Used for | New vulnerability checks, licence review, procurement | | Limit | Lists parts only; patch status and exploitability need separate checks |
Is an SBOM required by law
**In US federal procurement, and for EU manufacturers from December 2027.** | Region | Basis | Date | Detail | |---|---|---|---| | US | Executive Order 14028 | May 2021 | Basis for requiring SBOMs from federal software suppliers | | US | OMB guidance | 2022 | Agencies use SBOMs aligned with CISA guidance | | US | CISA draft minimum elements update | August 22, 2025 | Adds hash, licence, tool name, etc. | | EU | Cyber Resilience Act reporting | September 11, 2026 | Early warning on exploited bugs within 24 hours | | EU | Cyber Resilience Act full application | December 11, 2027 | Essential requirements including an SBOM |
SPDX vs CycloneDX
**Both are standard SBOM formats with different origins.** | Item | SPDX | CycloneDX | |---|---|---| | Origin | Linux Foundation, licence compliance | OWASP, security analysis | | Strength | Licence and copyright data | Vulnerability and dependency links | | International standard | ISO/IEC 5962 | ECMA-424 | | Common ground | Machine-readable (JSON etc.), many generators | — |

In December 2021, security teams worldwide spent weeks on one question: "Where in our systems is Log4j?" When a remote-code-execution flaw (Log4Shell) was disclosed in the Java logging library Log4j, most organisations could not immediately say whether their software contained it. Of the nearly 80 organisations the US Cyber Safety Review Board examined in its first report, none used a software inventory to locate vulnerable deployments. That inventory is an SBOM — a software bill of materials. In autumn 2026, as Anthropic offers free AI security scans to open-source projects ("Anthropic Cyber Mission") and the EU's manufacturer reporting duties begin, the list is being called back as the starting point of security.

1. What goes into an SBOM

Like the ingredients label on food, an SBOM records what software is made of. The difference is that it is written for machines, so it can be matched automatically against new vulnerability lists.

ElementMeaningExample
Component nameLibrary or package includedlog4j-core
VersionExact version number2.14.1
SupplierWho made itApache Software Foundation
Unique identifierDistinguishes same-named partsPackage URL (purl) etc.
Dependency relationshipsWhich part pulls in whichApp → framework → log4j
Author and timestampWho produced the list, whenBuild system, date
Hash and licence (added in 2025 draft)Integrity and terms of useSHA-256, Apache-2.0

The most important element is dependencies. A developer may add dozens of libraries directly, but those pull in hundreds of indirect ("transitive") components. Log4j was hard to find because it usually sat deep in those transitive layers.

2. With and without an SBOM

SituationWithout SBOMWith SBOM
New vulnerability disclosedAsk every dev team and vendorSearch the list
Purchased softwareWait for vendor answersCheck the supplied list yourself
Licence reviewManual, just before releaseAutomatic on every build
Post-incident reportingEstimate the blast radiusIdentify affected products and versions
Time taken (Log4j)Days to weeksMinutes to hours

Tenable noted that during Log4j most vendors did not provide SBOMs, so response teams had to contact each vendor, a process it called arduous, redundant and time-consuming. The 2022 Open Source Security and Risk Analysis (OSSRA) report likewise traced the round-the-clock scramble to organisations not knowing where Log4j was, or whether they had it at all.

An SBOM is necessary but not sufficient. It says what is inside, not whether a component is patched or reachable by an attacker. That is why SBOMs are often paired with VEX (Vulnerability Exploitability eXchange) documents stating whether a given flaw is actually exploitable in a product.

3. Who requires it — from US procurement to EU law

DateRegionWhat was set
May 2021USCybersecurity Executive Order 14028 — basis for SBOM requirements on federal software suppliers
July 2021USNTIA publishes SBOM minimum elements
December 2021GlobalLog4j vulnerability (Log4Shell) disclosed
2022USOMB guidance — agencies use SBOMs aligned with CISA guidance
December 10, 2024EUCyber Resilience Act (CRA) enters into force
August 22, 2025USCISA publishes draft update to minimum elements (hash, licence, tool name, generation context)
September 11, 2026EUCRA reporting begins — early warning within 24 hours, notification within 72 hours for exploited vulnerabilities
December 11, 2027EUCRA fully applies — essential requirements including an SBOM

The CRA covers "products with digital elements" sold in the EU, including those from non-EU makers. Compliance guides say fines can reach €15 million or 2.5% of global annual turnover, whichever is higher. CISA's draft names SPDX and CycloneDX as automation-friendly formats and acknowledges that SaaS and AI software are hard to capture in traditional SBOM models.

FormatOriginStrengthInternational standard
SPDXLinux FoundationLicence and copyright dataISO/IEC 5962
CycloneDXOWASPSecurity analysis, dependenciesECMA-424

4. SBOMs in the AI era — open issues and what is unconfirmed

  • AI bills of materials: AI systems include model weights, training data and external APIs as well as code. "AI-BOM" proposals exist but no settled standard; CISA's draft left AI software as an open challenge.
  • A flood of AI-found bugs: AI scanners find candidate vulnerabilities faster than humans can review them. Knowing which components sit where is what makes prioritisation possible.
  • CISA final version: Whether the 2025 minimum elements were finalised, and how they differ from the draft, was not confirmed.
  • Deadline wording: Some CRA reporting deadlines are described slightly differently across guides; the regulation's text is the reference.

Sources

  1. CISA — 2025 Minimum Elements for a Software Bill of Materials (SBOM)
  2. SC Media — CISA releases draft changes to SBOM minimum requirements for comment
  3. Sonatype — What Federal Agencies Need to Know About CISA's 2025 SBOM Minimum Elements
  4. TechTarget — EU Cyber Resilience Act reporting: What CISOs need to know
  5. noze — Cyber Resilience Act: SBOM and vulnerability reporting incoming (also for Open Source)
  6. Tenable — Apache Log4j Flaw Puts Third-Party Software in the Spotlight
  7. The New Stack — Open source news from the 2022 OSSRA report

Verification

Published
Last modified
Cross-check
Checked against 7 independent sources.
Unverified
  • CISA's 2025 minimum elements went through public comment after the August 2025 draft (closing October 3, 2025). Whether a final version has been issued, and how it differs, was not confirmed.
  • The Cyber Safety Review Board figure (none of nearly 80 organisations used software inventories) comes from reporting on the board's first report; no broader independent count was found.
  • Detailed Cyber Resilience Act deadlines (such as final-report timing) are worded slightly differently across guides; check Regulation (EU) 2024/2847 and Commission guidance.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related